Awesome AI AgentsRuntime Analysis Tools

invariantlabs-ai/mcp-scan

⭐ 3035 Python added to this list on 2025-06-16 repository created 2025-04-07

MCP-Scan is a comprehensive security scanning and monitoring tool designed specifically for MCP (Model Context Protocol) connections. It aims to identify and mitigate common security vulnerabilities such as prompt injections, tool poisoning, and cross-origin escalations that can compromise the integrity and security of MCP-based systems. The tool operates in two primary modes: static scanning and dynamic proxy monitoring. In the static scanning mode (`mcp-scan scan`), MCP-Scan analyzes installed MCP servers and their configurations to detect malicious tool descriptions and potential security threats. This includes identifying tool poisoning attacks, cross-origin escalations, and rug pull attacks by examining the tools and prompts used within the MCP environment. The scanning process supports various MCP client configurations, including Claude, Cursor, and Windsurf, ensuring broad compatibility. The dynamic proxy mode (`mcp-scan proxy`) provides real-time monitoring and control over MCP traffic. By acting as a proxy server, it intercepts and logs all MCP communications, allowing for continuous security oversight. This mode enables the enforcement of guardrail policies that restrict and validate tool calls and responses, including detection of personally identifiable information (PII), secrets, and other sensitive data. Users can define custom guardrails using a flexible configuration system to tailor security policies to their specific needs. MCP-Scan integrates with Invariant Guardrails for advanced policy enforcement and uses hashing techniques to detect unauthorized changes to MCP tools. It offers detailed logging and auditing capabilities, making it suitable for both security researchers and practitioners who need to safeguard their MCP environments. The tool emphasizes privacy by not storing or logging user data beyond tool descriptions and scan results. Overall, MCP-Scan is a vital security utility for anyone using MCP connections, providing both preventative and detective controls to maintain the security and integrity of their AI tool ecosystems.

https://github.com/invariantlabs-ai/mcp-scan

agentaiauditcross-origin-escalationdynamic-proxyguardrailsinvariant-guardrailsloggingmcpmcp-connectionsmcp-toolsmodelcontextprotocolpii-detectionprompt-injectionreal-time-monitoringsecrets-detectionsecuritysecurity-scannersecurity-vulnerabilitiesstatic-scanningtool-poisoningtool-restrictions

Also in Runtime Analysis Tools

zylon-ai/private-gpt

PrivateGPT is a fully private, offline-capable AI platform that enables users to interact with their documents using Large Language Models through a comprehensive API and user-friendly interface, ensuring data never leaves the user's environment.

vxcontrol/pentagi

PentAGI is a fully autonomous AI-driven penetration testing system that integrates professional security tools, multi-agent AI collaboration, and scalable microservices architecture to deliver comprehensive and automated security assessments.

fortra/impacket

Impacket is a Python library offering low-level programmatic access and implementations for various network protocols, focusing on security research and educational use.

FunnyWolf/Viper

VIPER is a versatile and powerful red team platform that supports adversary simulation and cybersecurity assessments across multiple operating systems, enhanced with AI-driven automation and extensive post-exploitation capabilities.

openrecall/openrecall

OpenRecall is a fully open-source, privacy-focused digital memory tool that captures and makes searchable your digital history through screenshots, supporting Windows, macOS, and Linux with local data storage and advanced semantic search capabilities.

miscusi-peek/cheatengine-mcp-bridge

MCP server that exposes Cheat Engine memory reading, scanning, disassembly and debugging to AI agent clients through roughly 180 tools over a named pipe or TCP relay.

amonapp/amon

Amon is a modern, open-source server monitoring platform designed to help users track and manage server performance and uptime effectively.

cisco-ai-defense/mcp-scanner

Cisco AI Defense security scanner that inspects MCP servers, tools, prompts and resources for malicious behavior using YARA rules, an LLM-as-a-judge engine and the Cisco AI Defense inspect API.